Show filters
65 Total Results
Displaying 11-20 of 65
Sort by:
Attacker Value
Unknown

CVE-2023-5131

Disclosure Date: January 18, 2024 (last updated January 25, 2024)
A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.
Attacker Value
Unknown

CVE-2023-6888

Disclosure Date: December 17, 2023 (last updated December 21, 2023)
A vulnerability classified as critical was found in PHZ76 RtspServer 1.0.0. This vulnerability affects the function ParseRequestLine of the file RtspMesaage.cpp. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248248. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-33842

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 requires the end user to have access to the server SSL key which could allow a local user to decrypt and obtain sensitive information. IBM X-Force ID: 256117.
Attacker Value
Unknown

CVE-2021-38959

Disclosure Date: November 16, 2021 (last updated February 23, 2025)
IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of service by writing arbitrary files to admin protected directories on the system. IBM X-Force ID: 212046.
Attacker Value
Unknown

CVE-2020-24509

Disclosure Date: June 09, 2021 (last updated February 22, 2025)
Insufficient control flow management in subsystem in Intel(R) SPS versions before SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.04.023.0, or SPS_E5_04.04.03.263.0 may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2020-4717

Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in another protected path during product installation. IBM X-Force ID: 187727.
Attacker Value
Unknown

CVE-2020-27280

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.
Attacker Value
Unknown

CVE-2020-8705

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.
Attacker Value
Unknown

CVE-2018-1772

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
IBM SPSS Analytic Server 3.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148689.
0
Attacker Value
Unknown

CVE-2018-14800

Disclosure Date: October 03, 2018 (last updated November 27, 2024)
Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to cause the application to read past the boundary allocated to a stack object, which could allow execution of code under the context of the application.
0